×

Method and apparatus for transitioning between states of security policies used to secure electronic documents

  • US 8,127,366 B2
  • Filed: 09/30/2003
  • Issued: 02/28/2012
  • Est. Priority Date: 09/30/2003
  • Status: Active Grant
First Claim
Patent Images

1. A document security system for restricting access to secured documents, the system comprising:

  • a processor;

    a policy system configured to enable the processor to store at least one process-driven security policy on a computer readable storage medium, wherein the process-driven security policy includes a plurality of different states and transition rules, wherein each of the different states is associated with one or more access restrictions, wherein at least one of the different states has distinct access restrictions for secured documents which reside in that state, and wherein the transition rules specify circumstances under which a secured document is to transition from one state to another, wherein the secured document includes at least a security information portion and an encrypted data portion, the security information portion including at least an encrypted file key, wherein the circumstances include the occurrence of internal and external events, wherein the external events originate from outside the policy system and wherein in response to detecting a transition from a previous state of the process-driven security policy for the secured document to a current state, the secured document is modified by decrypting the file key and then re-encrypting the file key, whereby the file key is encrypted differently for the current state than the previous state;

    wherein the policy system is configured to enable the processor to provide a reference to the process-driven security policy to a client computer, the reference referring to the process-driven security policy and an accessor user list resident on the policy system; and

    an access manager configured to enable the processor to access the process-driven security policy and determine whether a requestor is permitted to access a secured document based on the policy state associated therewith at the time access is requested, the requestor being listed in the accessor user list, and the corresponding one or more access restrictions thereof for the process-driven security policy.

View all claims
  • 4 Assignments
Timeline View
Assignment View
    ×
    ×